s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.elibomi

📛 Threat Title

Malware family: Elibomi

Category: Elibomi First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.elibomi`. Printable name: Elibomi. Aliases: Drinik.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.elibomi VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.elibomi

IOC database

Type
domain
Value
apk.elibomi
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.elibomi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.elibomi

References (1)

Remediations (10)

  • web:dl.acm.org

    In response, Artificial Intelligence (AI) models are increasingly leveraged to enhance malware classification and remediation efforts. However, while such models trained to classify malware datasets often perform well in controlled environments, research increasingly shows that conventional AI-based malware classifiers struggle to generalize to ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Elibomi malware family including references, samples and yara signatures.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.enigmasoftware.com

    A new family of phishing Android malware has been spotted being used in live attacks by cybercriminals. The threat was discovered by the researchers who named it Elibomi . The threat relies on social engineering tactics and fake Android applications to collect information from its victims and exfiltrate it to servers under the control of the hackers. First Elibomi Attack The first attack ...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.pcrisk.com

    Elibomi malware overview As mentioned in the introduction, there are several versions of Elibomi . The latest variants employ the Android Accessibility Services to gain access and control over compromised devices. Cyber criminals may gain near-user-level control of the system by abusing these services.

  • web:www.sciencedirect.com

    It is essential to do malware detection analyses since malware is becoming more sophisticated and prevalent. Numerous researchers work to counteract Android malware intrusions in different ways. Malware detection and classification work best with large datasets that contain all current malware types.

  • web:www.trendmicro.com

    As of this writing, we observed five banking malware families involved in these attacks, namely Elibomi , FakeReward, AxBanker, IcRAT, and IcSpy. We analyzed that the bank customers targeted include account subscribers of seven banks, including some of the most well-known banks located in the country and potentially affecting millions of customers.

  • web:zimperium.com

    Elibomi is Android malware actively targeting users, particularly in India, by masquerading as legitimate applications to steal sensitive personal and financial information. Its evolution and sophisticated techniques underscore the critical importance of mobile app security for developers and organizations, especially those in the enterprise sector.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.